CVE-2001-0537
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.
- Affected products
- Cisco Ios
- Cisco Ios
- = 11.3, 11.3aa, 11.3da, 11.3db, 11.3ha, 11.3ma, 11.3na, 11.3t, 11.3xa, 12.0, 12.0\(5\)xk, 12.0\(7\)xk, 12.0\(10\)w5\(18g\), 12.0\(14\)w5\(20\), 12.0da, 12.0db, 12.0dc, 12.0s, 12.0sc, 12.0sl, 12.0st, 12.0t, 12.0wc, 12.0wt, 12.0xa, 12.0xb, 12.0xc, 12.0xd, 12.0xe, 12.0xf, 12.0xg, 12.0xh, 12.0xi, 12.0xj, 12.0xl, 12.0xm, 12.0xn, 12.0xp, 12.0xq, 12.0xr
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 68.5% (99th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2002-03-09
CVE-2001-0537 at NVD
11 known exploits for CVE-2001-0537
Proof-of-concept code and exploit modules indexed by Sploitus
Cisco IOS HTTP Unauthorized Administrative Access
Exploit for CVE-2000-0114
Cisco IOS HTTP access level authentication bypass
Cisco IOS HTTP access level authentication bypass
Cisco IOS HTTP access level authentication bypass
Cisco IOS HTTP access level authentication bypass
Cisco IOS HTTP Unauthorized Administrative Access
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (1)
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (2)
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (4)
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (3)